Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
List Site Pro用户数据库定界符注入漏洞
Vulnerability Description
List Site PRO是一款站点排名系统,可以对各个成员站点进行统计,并根据点击结果进行排名。 List Site PRO对用户提交的数据缺少正确过滤,远程攻击者可以利用这个漏洞注入定界符,更改帐户信息。 通过注册和在部分字段注入'|'符来控制其他用户帐户信息,List Site Pro使用'|'来定界数据库,但是没有对输入数据进行定界符检查,因此用户如果输入如下内容: username:username email:email@emial.com url:www.url.com bannerurl:
CVSS Information
N/A
Vulnerability Type
N/A